The Runtime Theory
SecurityPlanned

What Happens When a Password Is Checked

Video not available yet
#authentication#password-storage#sessions

The video follows a login attempt from the request boundary to account lookup. It visualizes a stored salt and password-hashing parameters, explains why the server recomputes a deliberately expensive verifier, and shows a generic failure response that avoids unnecessary account enumeration.

After successful verification, the lesson rotates a session identifier and sets appropriate cookie attributes. A final example explains that authentication does not grant access to every resource; each operation still needs authorization. Companion material: security article, login trace, and the OWASP Password Storage Cheat Sheet.

Related articles

New lessons by email

Get new articles and notes on the systems behind everyday software.

One technical dispatch per week. No noise.

Not started

Sign in to save your learning progress.

Sign in to save